cKure
@cKure
6.59K
subscribers
1.35K
photos
320
videos
270
files
12K
links
﷽
This channel was created in 2018 and contains content from the information security domain.
This channel is primarily run by AI bots (n8n).
Archive:
ckure.esy.es
Criticals:
@ckuRED
linkedin.com/company/ckure
Support
📨
i@ckure.org
Download Telegram
Join
cKure
6.59K subscribers
cKure
https://techcrunch.com/2018/07/19/vacuum-vulnerability-hack-diqee-positive-technologies/amp/
TechCrunch
A vacuum vulnerability could mean your Roomba knockoff is hoovering up surveillance
Yet again we are reminded that the mild conveniences of the smart home are all well and good, right up until someone decides to turn one of those
cKure
https://n0where.net/what-the-fuzz-radamsa
cKure
https://keenlab.tencent.com/en/2018/07/19/Exploiting-iOS-11-0-11-3-1-Multi-path-TCP-A-walk-through/
Keen Security Lab Blog
Exploiting iOS 11.0-11.3.1 Multi-path-TCP:A walk through
IntroductionThe iOS 11 mptcp bug (CVE-2018-4241) discovered by Ian Beer is a serious kernel vulnerability which involves a buffer overflow in mptcp_usr_connectx that allows attackers to execute arbitr
cKure
https://amp.tomshardware.com/news/cisco-backdoor-hardcoded-accounts-software,37480.html
Tom's Hardware
Backdoors Keep Appearing In Cisco's Routers
Five different backdoors were found in Cisco's software this year, and Cisco's history with backdoors goes back many years.
cKure
https://www.bleepingcomputer.com/news/security/half-a-billion-iot-devices-vulnerable-to-dns-rebinding-attacks/
BleepingComputer
Half a Billion IoT Devices Vulnerable to DNS Rebinding Attacks
Armis, the cyber-security firm that discovered the BlueBorne vulnerabilities in the Bluetooth protocol, warns that nearly half a billion of today's "smart" devices are vulnerable to a decade-old attack known as DNS rebinding.
cKure
https://n0where.net/microsoft-azure-cloud-security-auditing-azurite
cKure
https://www.eff.org/deeplinks/2018/07/between-you-me-and-google-problems-gmails-confidential-mode
Electronic Frontier Foundation
Between You, Me, and Google: Problems With Gmail's “Confidential Mode”
With Gmail’s new design rolled out to more and more users, many have had a chance to try out its new “Confidential Mode.” While many of its features sound promising, what “Confidential Mode” provides
cKure
https://opnsec.com/2018/07/into-the-borg-ssrf-inside-google-production-network/
OpnSec
Into the Borg – SSRF inside Google production network | OpnSec
Intro - Testing Google Sites and Google Caja In March 2018, I reported an XSS in Google Caja, a tool to securely embed arbitrary html/javascript in a webpage. In May 2018, after the XSS was fixed, I r
cKure
https://posts.specterops.io/hunting-for-bad-apples-part-2-6f2d01b1f7d3
Medium
Hunting for Bad Apples — Part 2
In the previous post in this series, I introduced the use case of an attacker persisting via a LaunchAgent/Daemon, and a few osquery…
cKure
https://www.hackread.com/googleusercontent-cdn-hosting-images-infected-with-malware
Hackread - Latest Cybersecurity, Tech, Crypto & Hacking News
GoogleUserContent CDN Hosting Images Infected with Malware
The injected malware uses EXIF format to hide the code and the compromised images are available on Google+ and GoogleUserContent sites.
cKure
https://n0where.net/packet-capture-utility-stenographer
cKure
Someone published a POC for CVE-2018-2893, a vulnerability in Oracle WebLogic servers
https://github.com/anbai-inc/CVE-2018-2893/
cKure
https://n0where.net/best-web-application-vulnerability-scanners
cKure
cKure
https://0day.city/0day-18550.html
cKure
https://0day.city/0day-18549.html
cKure
https://0day.city/cve-2018-3770.html
cKure
https://blog.apnic.net/2018/07/19/artemis-neutralizing-bgp-hijacking-within-a-minute/
APNIC Blog
ARTEMIS — neutralizing BGP hijacking within a minute | APNIC Blog
Guest Post: ARTEMIS is a new defence system for network operators that can reduce BGP hijack detection and mitigation times from hours/days to a few seconds or minutes.
cKure
https://portswigger.net/daily-swig/xss-protection-disappears-from-microsoft-edge
The Daily Swig | Cybersecurity news and views
XSS protection disappears from Microsoft Edge
#NoFilter
cKure
https://n0where.net/reverse-engineering-android-apk-files-apktool
cKure
https://www.rotlogix.com/blog/2018/7/21/reverse-engineering-the-xigncode-anti-cheat-library-anti-debugging